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IN THE CLAIMS 

Amended claims follow. Insertions are imderlined. while deletions are struck out. The 
status of each claim is included prior to each heading. 

1 . (Previously Amended) A method for optimizing the operation of an anti-virus 
computer program for use with an operating system, comprising the steps of: 

detecting a request for closure of an opened computer file; 

determining in response to and after a closure request, but before file closure, if 
the opened computer file has been modified since being opened; 

scanning said opened file for viruses before closure only if said opened file has 
been modified; and 

closing said file if unmodified, and closing said file after scanning for vimses if 
found virus fi'ee. 

2. (Original) The method of Claim 1, further including before said detecting step, 
the steps of: 

determining whether said operating system includes a "dirty cache buffer" to 
raise or set a modification flag relative to a file being modified during the time it has been 
open, a computer code being indicative of said flag; and 

using the computer code for a raised or set modification flag. If available, for 
carrying out said modification determining step by checking for the presence of a raised 
modification for said file. 



3. (Original) The method of Claim 2, wherein if it is determined that said operating 
system does not provide a file modification flag, said method fiirther includes the steps 
of: 

estabhshing a "dirty cache buffer"; and 

raising a modification flag in said "dirty cache buffer^' if an opened file associated 
with said flag has been modified by a write operation. 

4. (Original) The method of Claim 1 . wherein said operating system includes a 
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"dirty cache buffer" for providing a computer code for a modification flag indicative of 
the modification of an open file, said method further including in said modification 
determining step, the step of: 

detecting the presence of said modification flag to determine if the associated 
opened file has been modified. 

5. (Previously Amended) The method of claim 4, further including the steps of: 
scanning a file for viruses in response to a request for opening the file; 
opening said file if virus fi-ee; 

establishing a cache buffer memory for storing upon opening of a file only a virus 
vulnerable portion of that file that a virus must use to enter and infect said file; 
said modification determining step including the steps of: 

indicating an open file is unmodified in the absence of an associated modification 

flag; 

responding to the presence of a modification flag by comparing a portion of said 
open file to the associated uimiodified virus vulnerable portion of said file in said cache 
buffer memory to determine if the portion of the open file has been modified since the 
opening of the file; 

indicating the opened file is unmodified if the virus vulnerable portion is 
unmodified; and 

indicating the opened file is modified if the virus vulnerable portion is modified. 

6. (Original) The method of Claim 1 , wherein said step of determining in response to 
a closing request if the opened computer file has been modified since being opened 
includes the step of: 

monitoring network protocols to determining if a write packet was initiated for a 
given open file. 

7. (Previously Amended) A method for optimizing operation of an anti-virus 
program in an operating system, said operating system including programming for raising 
a flag indicative of modification of an open file during the time the file has been open, 
said method including the steps of: 
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detecting the event of a request for closing said file being made to said operating 

system; 

after said detecting, but before file closure, determining whether said modification 
flag has been raised by said operating system for said open file; 

scanning said open file, in response to said modification flag, for viruses before 
permitting said operating system to close said file; and 

skipping said step of scanning for viruses before closure of said open file, 
whenever said modification flag is not present, 

8. (Previously Amended) A method for optimizing the operation of an anti-virus 
program in use in an operating system, said operating system including programming for 
raising a flag indicative of modification of an open file during the time the file has been 
open, said method including the steps of: 

scanning a file for viruses in response to a request from an associated computer 
user to open and gain access to said file; 

permitting said file to be opened if virus firee; 

storing upon opening a virus vulnerable unmodified portion of said open file; 
detecting the event of a request for closing said open file being made to said 
operating system; 

after said detecting, but before file closure, determining whether said modification 
flag has been raised by said operating system for said open file; 

scanning said open file, in response to said modification flag, for viruses before 
permitting said operating system to close said file; 

skipping said step of scanning for viruses before closure of said open file, 
whenever said modification flag is not present; 

responding to the presence of a modification flag by comparing the stored 
unmodified virus vulnerable portion of said file to the associated portion of said open file 
to determine if that portion has been modified during the time the file has been open; and 

skipping said step of scanning for viruses before closure of said open file if the 
virus vulnerable portion of said open file is unmodified. 

9. (Previously Amended) A computer program product embodied on a computer 
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readable medium for detecting computer viruses on a file server, the file server providing 
file storage and retrieval services for at least one client computer over a network, said 
computer program product comprising: 

computer code for detecling an open request from a client computer, the open 
request asking for a requested file from the file server; 

computer code for scanning said requested file for computer viruses, whereby the 
file server is permitted to provide said requested file to the client computer if no 
computer viruses are found therein; 

computer code for detecting a close request firom the client computer associated 
with said requested file; 

computer code for, after said delecting, but before file closure, accessing 
operating system flag that indicates whether the requested file was changed prior to said 
close request; 

computer code for scanning said requested file for computer viruses if said 
requested file was changed prior to said close request; and 

computer code for skipping scanning said requested file if it was not changed 
prior to said close request. 

10. (Original) The computer program product of claim 9, wherein said operating 
system flag is generated externally to said computer program product by the operating 
system in order to reduce redundant disk writes, whereby said computer code for 
scanning is invoked upon closing of the requested file only when actual disk writes are 
made by the operating system for the requested file. 

1 1. (Original) The computer program product of claim 10, wherein said computer 
code for accessing uses a file handle generated by the operating system to identify the 
operating system flag corresponding to the requested file, said handle having been 
generated when the file was opened. 

12. (Previously Amended) A computer program product embodied on a computer 
readable medium for detecting computer viruses on a file server, the file server providing 
file storage and retrieval services for at least one client computer over a network, said 
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computer program product comprising: 

computer code for detecting an open request jfrom a client computer, the open 
request asking for a requested file from the file server; 

computer code for scanning said requested file for computer viruses, whereby the 
file server is permitted to provide said requested file to the client computer if no 
computer viruses are found therein; 

computer code for detecting a close request fi-om the client computer associated 
with said requested file; 

computer code for, after said detecting, but before file closure, accessing an 
operating system flag that indicates whether the requested file was changed prior to said 
close request; 

computer code for skipping scanning said requested file if it was not changed 
prior to said close request; 

computer code responsive to said requested file having been changed prior to said 
close request for determining whether a virus vulnerable portion of said file was changed; 

computer code for skipping scanning said requested file if a virus vulnerable 
portion of said file was not changed prior to said close request; and 

computer code for scanning said requested file if a virus vulnerable portion of 
said file was changed prior to said close request 

1 3 . (Original) The computer program product of claim 1 2, wherein said 
operating system flag is generated externally to said computer program product by the 
operating system in order to reduce redundant disk writes, whereby said computer code 
for scanning is invoked upon closing of the requested file only when actual disk writes 
are made by the operating system for the requested file. 

14. (Original) The computer program product of claim 13, wherein said 
computer code for accessing uses a file handle generated by the operating system to 
identify the operating system flag corresponding to the requested file, said handle having 
been generated when the file was opened. 

15. (Previously Presented) A method for optimizing the operation of an anti- 
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virus compute program tor use »i.h an oper«mg system, ccmpnsrng the s.ep= of. 

detectmg. request for closure of an opened computer me; 

detennining in response to and after a closure request, but before file closure, .f 
Ure opened computer file has been modified since being opened; 

scamting said opened file for viruses before closure only ,f sard open«i file has 

been modified; and . ^ • 

closing said file if unmodified, and closing said file after scanmng for viruses rf 

found virus free; 

Wherein said operaUfg system includes a "dirty cache buffer- for provdrng a 
computer code for a modification flag indicafive of the modification of an open ffle, ^.d 
method further including in said modification detennining step, the step of detechng the 
presence of said modification fl^ u, detem,ine if the associated opened file has been 
modified; 

wherein further included are the steps of: 

scanning a file for viruses in response to a request for opemng the file, 
opening said file if virus firee, and 

establishing a cache buffer memory for storing upon opening of a file only 
a virus vulnerable portion of that file that a virus must use to enter and infect saad 

file; . 
wherein said modification detennining step includes the steps of: 

indicating an open file is unmodified in the absence of an associated 
modification flag, 

responding to the presence of a modification flag by comparmg a portion 
of said open file to the associated unmodified virus vulnerable portion of said file 
in said cache buffer memory to determine if the portion of the open file has been 
modified since the opening of the file, 

indicating the opened file is unmodified if the vims vulnerable poruon is 

' unmodified, and 

indicating the opened file is modified if the virus vulnerable portion is 

modified. 
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